48 CFR 252.204-7012
Listed by: NARA Registry, DoD Registry, Related authorities
Designation evidence
- NARA authority row: 48 CFR 252.204-7012 | status: Specified | banner: CUI//SP-CTI.
- DoD authority row: 48 CFR 252.204-7012. DoD lists this citation for the category; this DoD detail page does not display a separate Basic/Specified field.
- Related authority evidence: 48 CFR 252.204-7012 | status: Specified | banner: CUI//SP-CTI
- Related authority evidence: DoD lists this authority for the category; the linked authority text is extracted below when available.
- Registry designation context: Specified, CUI//SP-CTI. The linked authority text contains category-scope or applicability language that helps determine when the information falls within this CUI category. The linked authority text contains disclosure, access, protection, release, dissemination, or distribution-control language relevant to handling. The linked authority text contains violation, penalty, sanction, or enforcement language that may affect consequences for mishandling.
- Registry designation for this category is Specified with banner CUI//SP-CTI.
Extracted authority meaning
- 48 CFR 252.204-7012 authority text
- Registry designation context: Specified, CUI//SP-CTI. The linked authority text contains category-scope or applicability language that helps determine when the information falls within this CUI category. The linked authority text contains disclosure, access, protection, release, dissemination, or distribution-control language relevant to handling. The linked authority text contains violation, penalty, sanction, or enforcement language that may affect consequences for mishandling.
Operating conditions
- NARA category scope used with this authority: Controlled Technical Information means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. Controlled technical information is to be marked with one of the distribution statements B through F, in accordance with Department of Defense Instruction 5230.24, "Distribution Statements of Technical Documents." The term does not include information that is lawfully publicly available without restrictions. "Technical Information" means technical data or computer software, as those terms are defined in Defense Federal Acquisition Regulation Supplement clause 252.227-7013, "Rights in Technical Data - Noncommercial Items" (48 CFR 252.227-7013). Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.
- DoD category scope used with this authority: Technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. The term does not include information that is lawfully publicly available without restrictions. "Technical Information" means technical data or computer software, as those terms are defined in Defense Federal Acquisition Regulation Supplement clause 252.227-7013, "Rights in Technical Data - Noncommercial Items" (48 CFR 252.227-7013). "Technical information with military or space application" means any blueprints, drawings, plans, instructions, computer software and documentation that can be used, or be adapted for use, to design, engineer, produce, manufacture, operate, repair, overhaul, or reproduce any military or space equipment or technology concerning such equipment (10 U.S.C. 130).
- 48 CFR 252.204-7012 | status: Specified | banner: CUI//SP-CTI
- DoD lists this authority for the category; the linked authority text is extracted below when available.
- NARA registry status: Specified. Per-authority NARA status values: Specified. NARA banner marking evidence: CUI//SP-CTI. DoD registry requires dissemination control: Distribution Statement B thru F. The registry evidence is preserved here; detailed primary-law or regulation text analysis remains pending for this category.
- NARA category scope: Controlled Technical Information means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. Controlled technical information is to be marked with one of the distribution statements B through F, in accordance with Department of Defense Instruction 5230.24, "Distribution Statements of Technical Documents." The term does not include information that is lawfully publicly available without restrictions. "Technical Information" means technical data or computer software, as those terms are defined in Defense Federal Acquisition Regulation Supplement clause 252.227-7013, "Rights in Technical Data - Noncommercial Items" (48 CFR 252.227-7013). Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code.
- DoD category scope: Technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. The term does not include information that is lawfully publicly available without restrictions. "Technical Information" means technical data or computer software, as those terms are defined in Defense Federal Acquisition Regulation Supplement clause 252.227-7013, "Rights in Technical Data - Noncommercial Items" (48 CFR 252.227-7013). "Technical information with military or space application" means any blueprints, drawings, plans, instructions, computer software and documentation that can be used, or be adapted for use, to design, engineer, produce, manufacture, operate, repair, overhaul, or reproduce any military or space equipment or technology concerning such equipment (10 U.S.C. 130).
- DoD registry-required dissemination control: Distribution Statement B thru F
- Extracted authority condition: Covered defense information means unclassi- fied controlled technical information or other information, as described in the Con- trolled Unclassified Information (CUI) Reg- istry at category-list.html, that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Gov- ernmentwide policies, and is— (1) Marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of DoD in support of the performance of the contract; or (2) Collected, developed, received, trans- mitted, used, or stored by or on behalf of the contractor in support of the performance of the contract.
- Extracted authority condition: Controlled technical information means tech- nical information with military or space ap- plication that is subject to controls on the access, use, reproduction, modification, per- formance, display, release, disclosure, or dis- semination.
- Extracted authority condition: Information that is obtained from the contractor (or derived from information ob- tained from the contractor) under this clause that is not created by or for DoD is author- ized to be released outside of DoD— (1) To entities with missions that may be affected by such information; (2) To entities that may be called upon to assist in the diagnosis, detection, or mitiga- tion of cyber incidents; (3) To Government entities that conduct counterintelligence or law enforcement in- vestigations; (4) For national security purposes, includ- ing cyber situational awareness and defense purposes (including with Defense Industrial Base (DIB) participants in the program at 32 CFR part 236); or (5) To a support services contractor (‘‘re- cipient’’) that is directly supporting Govern- ment activities under a contract that in- cludes the clause at 252.204–7009, Limitations on the Use or Disclosure of Third-Party Con- tractor Reported Cyber Incident Informa- tion.
- Extracted authority condition: 394 48 CFR Ch. 2 (10–1–18 Edition) 252.204–7011 252.204–7011 [Reserved] 252.204–7012 Safeguarding covered de- fense information and cyber inci- dent reporting.
- Extracted authority condition: Technical information means technical data or computer software, as those terms are de- fined in the clause at DFARS 252.227–7013, Rights in Technical Data—Noncommercial Items, regardless of whether or not the clause is incorporated in this solicitation or contract.
Safeguarding and dissemination controls
- NARA registry control evidence: status Specified; banner marking CUI//SP-CTI.
- DoD required dissemination control: Distribution Statement B thru F
- DoD applicable policies: DFARS 204.73, DoDD 5000.01, DoDD 5230.25, DoDI 2030.08, DoDI 2040.02, DoDI 3200.12, DoDI 5000.02, DoDI 5200.39
- Nara basic or specified: Specified
- Nara authority rows: 48 CFR 252.204-7012 | status: Specified | banner: CUI//SP-CTI
- Nara banner markings: CUI//SP-CTI
- Dod required dissemination control: Distribution Statement B thru F
- Dod applicable policies: DFARS 204.73, DoDD 5000.01, DoDD 5230.25, DoDI 2030.08, DoDI 2040.02, DoDI 3200.12, DoDI 5000.02, DoDI 5200.39
- DoD registry lists Distribution Statement B thru F. Confirm whether the control is mandatory for the specific document, transaction, or dissemination context.
- Use the registry assertions, NARA authority rows, DoD authorities, DoD policies, warning statements, required dissemination controls, and examples first. Where the cited authority does not specify a handling detail, apply CUI Basic safeguards and dissemination rules so long as they do not conflict with the authority or agency-specific controls.
- Extracted authority control: Controlled technical information means tech- nical information with military or space ap- plication that is subject to controls on the access, use, reproduction, modification, per- formance, display, release, disclosure, or dis- semination.
- Extracted authority control: Covered defense information means unclassi- fied controlled technical information or other information, as described in the Con- trolled Unclassified Information (CUI) Reg- istry at category-list.html, that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Gov- ernmentwide policies, and is— (1) Marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of DoD in support of the performance of the contract; or (2) Collected, developed, received, trans- mitted, used, or stored by or on behalf of the contractor in support of the performance of the contract.
- Extracted authority control: 394 48 CFR Ch. 2 (10–1–18 Edition) 252.204–7011 252.204–7011 [Reserved] 252.204–7012 Safeguarding covered de- fense information and cyber inci- dent reporting.
- Extracted authority control: As used in this clause— Adequate security means protective meas- ures that are commensurate with the con- sequences and probability of loss, misuse, or unauthorized access to, or modification of information.
- Extracted authority control: Information that is obtained from the con- tractor (or derived from information ob- tained from the contractor) under this clause that is created by or for DoD (including the information submitted pursuant to para- graph (c) of this clause) is authorized to be used and released outside of DoD for pur- poses and activities authorized by paragraph (i) of this clause, and for any other lawful Government purpose or activity, subject to all applicable statutory, regulatory, and pol- icy based restrictions on the Government’s use and release of such information.
- Extracted authority control: Technical information means technical data or computer software, as those terms are de- fined in the clause at DFARS 252.227–7013, Rights in Technical Data—Noncommercial Items, regardless of whether or not the clause is incorporated in this solicitation or contract.
- Extracted authority control: Compromise means disclosure of informa- tion to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred.
Authority excerpts
Most relevant extracted authority passageControlled technical information means tech- nical information with military or space ap- plication that is subject to controls on the access, use, reproduction, modification, per- formance, display, release, disclosure, or dis- semination.
Extracted authority passage 2Covered defense information means unclassi- fied controlled technical information or other information, as described in the Con- trolled Unclassified Information (CUI) Reg- istry at category-list.html, that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Gov- ernmentwide policies, and is— (1) Marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of DoD in support of the performance of the contract; or (2) Collected, developed, received, trans- mitted, used, or stored by or on behalf of the contractor in support of the performance of the contract.
Extracted authority passage 3394 48 CFR Ch. 2 (10–1–18 Edition) 252.204–7011 252.204–7011 [Reserved] 252.204–7012 Safeguarding covered de- fense information and cyber inci- dent reporting.
Extracted authority passage 4As used in this clause— Adequate security means protective meas- ures that are commensurate with the con- sequences and probability of loss, misuse, or unauthorized access to, or modification of information.
Extracted authority passage 5Information that is obtained from the con- tractor (or derived from information ob- tained from the contractor) under this clause that is created by or for DoD (including the information submitted pursuant to para- graph (c) of this clause) is authorized to be used and released outside of DoD for pur- poses and activities authorized by paragraph (i) of this clause, and for any other lawful Government purpose or activity, subject to all applicable statutory, regulatory, and pol- icy based restrictions on the Government’s use and release of such information.
Extracted authority passage 6Information that is obtained from the contractor (or derived from information ob- tained from the contractor) under this clause that is not created by or for DoD is author- ized to be released outside of DoD— (1) To entities with missions that may be affected by such information; (2) To entities that may be called upon to assist in the diagnosis, detection, or mitiga- tion of cyber incidents; (3) To Government entities that conduct counterintelligence or law enforcement in- vestigations; (4) For national security purposes, includ- ing cyber situational awareness and defense purposes (including with Defense Industrial Base (DIB) participants in the program at 32 CFR part 236); or (5) To a support services contractor (‘‘re- cipient’’) that is directly supporting Govern- ment activities under a contract that in- cludes the clause at 252.204–7009, Limitations on the Use or Disclosure of Third-Party Con- tractor Reported Cyber Incident Informa- tion.